Virtual asset service providers (VASPs) frequently operate as part of larger corporate groups, comprising various subsidiaries, affiliates, and parent companies. While a specific entity within such a group might directly offer virtual asset services, regulators are increasingly scrutinising the entire corporate structure to ensure comprehensive oversight.

This approach aims to prevent regulatory arbitrage, ensure financial stability across the group, and mitigate risks like money laundering and terrorist financing. Consequently, even non-operating parent companies could find themselves drawn into the regulatory net, facing new obligations under Pakistan’s evolving virtual asset framework.

Operators must therefore understand how their broader corporate structure influences their licensing requirements and ongoing compliance. Overlooking these group-level considerations could lead to significant regulatory challenges and potential enforcement actions.

What is a group structure in the context of virtual assets?

A group structure refers to a collection of legally distinct entities, such as subsidiaries, affiliates, and parent companies, that are linked by common ownership or control, often with the parent company at the apex. This framework is crucial for understanding how a single VASP might be influenced or controlled by related corporate bodies.

In Pakistan, the Securities and Exchange Commission of Pakistan (SECP) already provides definitions and oversight for corporate groups. These established principles are likely to inform how the Pakistan Virtual Assets Regulatory Authority (PVARA) views virtual asset businesses operating within complex corporate structures. It is not merely about direct ownership but also about significant influence, operational control, and shared resources that bind entities together.

Why do regulators care about group structures?

Regulators like PVARA are concerned with group structures to prevent regulatory gaps, ensure consistent risk management, and prevent illicit activities from exploiting weaknesses within a complex corporate setup. This holistic view is fundamental to effective supervision of the virtual asset sector.

The Financial Action Task Force (FATF) recommendations, which Pakistan is implementing, emphasise the importance of understanding beneficial ownership and applying group-wide Anti-Money Laundering (AML) and Counter-Terrorist Financing (CFT) controls. A fragmented regulatory approach, where only the direct VASP is scrutinised, could allow risks to materialise in unregulated parts of the group, ultimately affecting the stability and integrity of the licensed VASP. Regulators need to understand the full scope of operations, control, and potential liabilities across the entire corporate family. For more on this, see our article on beneficial ownership disclosure.

When might a parent company need a VASP licence?

A parent company might need a VASP licence if it directly performs regulated virtual asset activities, exerts significant operational control over a VASP subsidiary’s regulated functions, or is deemed by PVARA to be integral to the provision of virtual asset services. This extends beyond simple equity ownership to the substance of the activities performed.

While PVARA’s proposed framework is still under consultation, international regulatory trends suggest several scenarios where a parent company could be brought into the licensing perimeter:

PVARA’s interpretation of “performing virtual asset services” will likely focus on the economic reality and functional control, not solely the legal form. Operators should carefully assess who needs a VASP licence in Pakistan and who does not to avoid misinterpretations. For assistance with the application process, Sarzif Policy offers comprehensive VASP licensing services.

What are the implications for entities within a group?

All entities within a group, including parent companies, may face increased scrutiny regarding their governance, financial health, and adherence to compliance standards, even if only one entity holds the VASP licence. This extends the regulatory burden beyond the immediate operating VASP.

Key implications include:

How does PVARA approach group licensing?

PVARA’s proposed framework, drawing from FATF guidelines, indicates an intention to assess licensing applications within the context of the broader corporate group, focusing on control, risk management, and overall operational integrity. This means PVARA will likely look beyond the individual applicant.

PVARA, as Pakistan’s dedicated virtual asset regulator (learn more about what PVARA is), is expected to take a holistic view of an applicant’s business, including its parent company and other affiliates. The application process will likely demand detailed information about the entire group structure, including ownership charts, inter-company agreements, and financial relationships. While the specific details are still being finalised, operators should anticipate requirements for group-wide AML/CFT policies and risk management frameworks, even if specific operational duties are decentralised. The approach to corporate structuring for a Pakistani VASP will significantly impact these considerations. For the latest updates and proposed rules, operators should consult the official PVARA website: https://pvara.org.

What information must be disclosed about the group?

Applicants must typically disclose comprehensive details about their entire corporate group, including ownership structures, control mechanisms, financial relationships, and the identities of all beneficial owners and key management personnel. This transparency is vital for regulatory oversight.

Here is a list of common disclosures expected:

  1. Comprehensive Organisational Chart: A detailed diagram illustrating all entities within the group, their legal relationships, ownership percentages, and control structures.
  2. Beneficial Ownership Information: Full identification and verification of all ultimate beneficial owners (UBOs) across the entire corporate group, ensuring transparency about who ultimately owns or controls the VASP.
  3. Key Personnel Details: Information on directors, senior management, and compliance officers, not just of the applicant VASP, but also of the parent company and other relevant group entities, particularly concerning their fit and proper status.
  4. Financial Statements: Consolidated financial statements for the group, along with individual statements for the applicant VASP and any other significant entities.
  5. Inter-company Agreements: Copies of any agreements between group entities that relate to the VASP’s operations, such as shared services, technology provision, funding arrangements, or intellectual property licensing.
  6. Group-Level Risk Assessments: Documentation of group-wide risk assessments for AML/CFT, operational risks, and cybersecurity.
  7. Regulatory Status of Other Entities: Details of the regulatory status of other group entities in different jurisdictions, especially if they are also involved in virtual asset or financial services.

What are the potential challenges for group entities?

Group entities may face challenges including increased compliance costs, complex reporting requirements, potential conflicts of interest, and the need to harmonise policies and procedures across diverse business lines and jurisdictions. These complexities demand careful planning and resource allocation.

How can groups prepare for these regulations?

Groups should proactively map their corporate structure, identify all entities involved in or influencing virtual asset activities, conduct a group-wide risk assessment, and establish robust, harmonised compliance frameworks and governance structures. Early preparation is key to navigating the regulatory landscape successfully.

Here are practical steps for preparation:

  1. Conduct a Group-Wide Regulatory Mapping: Clearly identify all entities within the corporate group and assess their current and potential involvement in virtual asset activities. Determine which entities might fall within PVARA’s regulatory perimeter, directly or indirectly.
  2. Review Corporate Governance: Ensure clear lines of responsibility and accountability across the group, particularly for virtual asset operations. This includes defining roles for the board of directors and senior management at both the parent and subsidiary levels.
  3. Develop a Unified Compliance Framework: Establish a comprehensive AML/CFT framework that applies group-wide, covering policies, procedures, risk assessments, and staff training. This framework should be adaptable to specific jurisdictional requirements.
  4. Assess Financial and Operational Resilience: Evaluate the financial health and operational resilience of the entire group, ensuring adequate capital, liquidity, and robust IT systems to support the VASP’s activities.
  5. Engage with Experts: Seek advice from regulatory experts who understand Pakistan’s virtual asset framework and international best practices for group structures. This can help identify potential issues early and guide the application process.
Entity Type Primary Activity Potential Licensing Impact Key Considerations
Direct VASP Subsidiary Offers virtual asset services to customers Requires full VASP licence from PVARA. Must meet all capital, governance, AML/CFT, and operational requirements.
Parent Holding Company Holds equity in subsidiaries, provides group oversight May require licence if actively involved in VASP operations or deemed to control key functions. Scrutiny on control, financial support, group-wide policies, and beneficial ownership.
Shared Services Subsidiary Provides IT, HR, or back-office support to VASP entity Generally not licensed, but subject to outsourcing and third-party risk management rules. Must adhere to VASP’s compliance standards; VASP remains accountable for outsourced functions.

About this analysis

This analysis by Sarzif Policy is based on a review of publicly available consultation papers from PVARA, directives from the State Bank of Pakistan (SBP), guidelines from the Financial Action Task Force (FATF), and general principles of financial regulation as applied by bodies like the Securities and Exchange Commission of Pakistan (SECP) and the Federal Board of Revenue (FBR). While we strive for accuracy, Pakistan’s virtual asset regulatory framework is still at a consultation stage, and specific requirements are subject to change. Operators must verify all current details and obligations directly with PVARA or other relevant authorities. This article is intended for informational purposes only and does not constitute legal or regulatory advice.

Noor Aslam, Chief Executive Officer of Sarzif Policy

Noor Aslam

Chief Executive Officer of Sarzif Policy, with eight years in virtual assets — four of them advising on VARA licensing in Dubai. She leads the research team that tracks Pakistan's framework and reviews every consultant shortlist that goes out. More about the team.

This article is information, not legal or financial advice. Regulatory positions change. Confirm any requirement against the official position published by PVARA before you act on it. Spotted an error? Write to sarzifpolicy@gmail.com and we will correct it.

Related updates